It has clear GPL licensing, installation documentation, and a repository that matches the package. Its dependency-heavy CMS distribution also includes install and update hooks, increasing the cost of taking on an obsolete release.
8%
Total Score
50
50
75
Packagist marks the entire package as abandoned, with no replacement supplied. Package-level abandonment is a severe adoption risk for a dependency.
The latest registry release was published nearly 12 years ago, with no releases in the last 12 months. This strongly indicates that the release line is no longer maintained.
There were no commits and no active maintainers in the measured 3-month period. Combined with the archived repository, this confirms that current development has stopped.
The linked repository is archived, and its last push was nearly 9 years ago. An archived source project is a severe indicator that future maintenance is unavailable.
The package runs post-install and post-update Composer scripts. These are common for a framework distribution but add execution and maintenance complexity to an already obsolete dependency.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/dbal Version ~2.5@rc | — | — |
symfony/symfony Version ~2.5 | — | — |
twig/extensions Version ~1.0 | — | — |
nelmio/cors-bundle Version ~1.3 | — | — |
tedivm/stash-bundle Version 0.4.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.